Privacy Policy
What we collect, why we collect it, who sees it and how long we keep it. If you are a candidate, section 4 is the one about supervision — it is the question most people come here to answer.
1.Who is responsible for your data
This matters more than it sounds, because for most of the data on this platform we are not the organisation that decides what happens to it.
- Your organisation is the controller
- For candidate data — your enrolment, your attempts, your results, your supervision recordings — the organisation that enrolled you decides why it is collected and how long it is kept. Requests about that data start with them.
- We are the processor
- We hold and process that data on your organisation’s written instructions, under the Data Processing Agreement. We do not use it for our own purposes.
- We are the controller for our own data
- For visitors to this website, people who contact us, and the administrators of organisations we deal with commercially, we decide the purposes ourselves and this policy governs it directly.
Data protection contact: info@xamina.io. Our registration details are given on request.
2.What we collect
Account and identity
- Name, email address, and the organisation you belong to.
- Your locale and timezone, so times and messages arrive in a form you can use.
- Authentication data: a salted hash of your password (never the password itself), session and device records, and the times and IP addresses of sign-ins.
Assessment
- Enrolments, bookings, attempts, the answers you gave, timings and your results.
- Certificates issued to you, including the serial number that makes them verifiable.
Identity check-in, where your institution enables it
- An image of an identity document you photograph.
- A photograph of your face taken at check-in.
- A mathematical face template derived from those images, used to compare one against the other.
Supervision, where your institution enables it
- Still images from your webcam during the sitting, and from your shared screen if screen supervision is on.
- Integrity events — the record that a signal was detected, when, and how serious it was rated.
Technical
- Server logs including IP address, browser and pages requested, kept for security and troubleshooting.
- Strictly necessary cookies for your session and for cross-site request protection. We do not use advertising cookies or third-party trackers on this site.
3.Why we are allowed to collect it
Where we are the controller, we rely on these lawful bases under UK GDPR Article 6:
- Contract — to provide the service to an organisation and to the people using its account.
- Legitimate interests — to keep the platform secure, prevent abuse, and respond to enquiries you send us.
- Legal obligation — to keep accounting records and to answer lawful requests.
Where your institution is the controller, it is responsible for identifying its own lawful basis. Face images and face templates are biometric data used to identify you, which is special category data under Article 9. Your institution must have an Article 9 condition for it — usually explicit consent — and must tell you before you sit. The platform shows you a supervision notice and records that you saw it; that record supports your institution’s accountability, it does not replace it.
4.Supervision, in plain terms
If your institution has enabled supervision, here is what actually happens while you sit.
- Your webcam takes still images at intervals. It is not a continuous video recording and there is no audio recording.
- Those images are analysed for a fixed set of signals your organisation chose to switch on — for example a phone in view, your face not being present, a second person appearing, or your gaze leaving the screen.
- A signal your organisation has switched off is not analysed and no record of it is kept.
- When a signal is detected, an integrity event is recorded with the frame that triggered it, so a human can look at it afterwards and judge.
- A detection is not a decision. Nobody is failed by the software. Your organisation reviews the evidence under its own misconduct process.
You may refuse. Refusing means you cannot sit a supervised paper, and what happens next is a matter between you and your institution — talk to them, not to us.
5.Who we share it with
We do not sell personal data, and we never will.
- Your institution. Administrators, invigilators and examiners at the organisation that enrolled you can see your enrolment, attempts, results and any integrity events.
- Sub-processors. A short list of suppliers who host and run the service on our behalf, each under a written contract with the same obligations we owe you. The current list is in the Data Processing Agreement.
- Anyone verifying a certificate. A person holding your certificate serial can confirm it is genuine. The verification page shows only what is needed to confirm that — never your answers, your score breakdown or your supervision record.
- Authorities, where we are legally required to disclose. Unless we are prohibited, we will tell the controller first.
6.Where it is held
Candidate data is hosted in the EU. Where a sub-processor operates outside the UK or EEA, transfers are covered by the UK International Data Transfer Addendum or Standard Contractual Clauses, together with a transfer risk assessment.
Our outbound email is sent through Microsoft 365, so the contents of a message we send you — and your address — pass through that service.
7.How long we keep it
Where your institution is the controller, it sets retention and can instruct us to delete sooner. Our defaults, applied unless instructed otherwise:
- Results and certificates — kept for the life of the account, because a qualification that cannot be re-verified is worthless. the life of the account
- Identity check-in images — 90 days after the sitting, then deleted.
- Supervision frames — 180 days, or until the appeal window closes, then deleted.
- Audit and compliance events — 6 years, because they are the record that makes a result defensible.
- Server logs — 90 days.
8.Your rights
Under UK GDPR you have the right to:
- Know what is held about you, and get a copy of it.
- Have inaccurate data corrected.
- Have data erased, where there is no overriding reason to keep it.
- Restrict or object to processing in certain circumstances.
- Receive data you gave us in a portable format.
- Withdraw consent, where consent is what the processing rests on.
Where to send the request. If you are a candidate, send it to the institution that enrolled you — they are the controller and we are obliged to act on their instruction, not to act around them. If you send it to us, we will pass it to them and tell you we have. For data where we are the controller, write to info@xamina.io and we will respond within one month.
You can complain to the Information Commissioner’s Office at ico.org.uk. We would rather you came to us first, but you do not have to.
9.Security
Passwords are stored as salted scrypt hashes and are never recoverable. Sessions use rotating refresh tokens with reuse detection, so a stolen token invalidates the family it came from. Access between organisations is separated at the database layer rather than by application filtering.
Our internal information security policy, access control policy and incident response plan govern how our own staff handle your data. They are available to organisations under NDA during procurement.
If you believe you have found a vulnerability, write to info@xamina.io. Please do not test against live candidate data.
10.Changes
We will post any change here and update the review date at the top. Where a change materially affects how we handle personal data, we will notify account administrators by email before it takes effect.
Questions about this document go to info@xamina.io. If anything here conflicts with a signed agreement between us, the signed agreement wins.